Software /
code /
prosody-modules
File
mod_auth_ccert/README.markdown @ 5149:fa56ed2bacab
mod_unified_push: Add support for multiple token backends, including stoage
Now that we have ACLs by default, it is no longer necessary to be completely
stateless. On 0.12, using storage has benefits over JWT, because it does not
expose client JIDs to the push apps/services. In trunk, PASETO is stateless
and does not expose client JIDs.
author | Matthew Wild <mwild1@gmail.com> |
---|---|
date | Sat, 14 Jan 2023 14:31:37 +0000 |
parent | 4433:0e3f5f70a51d |
line wrap: on
line source
--- labels: - 'Stage-Alpha' - 'Type-Auth' summary: Client Certificate authentication module ... Introduction ============ This module implements PKI-style client certificate authentication. You will therefore need your own Certificate Authority. How to set that up is beyond the current scope of this document. Configuration ============= authentication = "ccert" certificate_match = "xmppaddr" -- or "email" c2s_ssl = { cafile = "/path/to/your/ca.pem"; capath = false; -- Disable capath inherited from built-in default verify = {"peer"; "client_once"}; -- Ask for client certificate verifyext = { -- Don't validate client certs as if they were server certs lsec_ignore_purpose = false } } Compatibility ============= ----------------- -------------- trunk Works 0.10 and later Works 0.9 and earlier Doesn't work ----------------- --------------